Improper resource allocation - Buffer overflow In dbus-broker
Description
An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 30-1 | ||
debian 13 | 30-1 | ||
debian 14 | 30-1 | ||
debian 11 | 26-1+deb11u1 | ||
rpm rhel9 | 0:28-5.1.el9_0 |
Aliases
1. 2. 3. 4. 5.